The European Banking Authority (EBA) has formally entered the discussion regarding the future of decentralized finance (DeFi) within the European Union. On September 24, the authority submitted a detailed response to the European Commission, outlining a series of recommendations for the ongoing review of the Markets in Crypto-Assets (MiCA) regulation. The submission focuses heavily on the role of intermediaries and the potential risks associated with decentralized lending activities.
At the heart of the EBA’s proposal is a call for a comprehensive cost-benefit analysis concerning new obligations for Crypto-Asset Service Providers (CASPs). These entities, which include various platforms and wallet providers, often act as the primary gateway for users to interact with decentralized protocols. The EBA suggests that the current regulatory framework may need to expand its reach to capture the nuances of intermediated DeFi access, ensuring that the protections afforded to traditional financial consumers are mirrored in the digital asset space.
Key Developments in the EBA Proposal
- The EBA recommends adding “intermediating crypto-asset borrowing and lending” to the official list of regulated services under the MiCA framework.
- A proposal has been made to establish specific requirements for CASPs that provide access to DeFi protocols through proprietary interfaces or specialized products.
- The authority suggests implementing a suite of consumer safeguards, including suitability assessments, mandatory risk disclosures, and caps on leverage.
- The submission explores the possibility of a certification process for lending protocols to verify their technical resilience against cyberattacks and smart contract vulnerabilities.
Expanding the Scope of MiCA for Intermediaries
The EBA’s recommendations highlight a perceived gap in the current MiCA framework regarding how users access decentralized protocols. While MiCA provides a robust structure for centralized exchanges and stablecoin issuers, the “intermediated” route—where a company-controlled application or interface facilitates a connection to an on-chain protocol—remains a complex area for regulators. The EBA is specifically targeting this layer of the ecosystem, suggesting that the entities providing these interfaces should bear more responsibility for the activities they facilitate.
By proposing the addition of borrowing and lending intermediation to the list of CASP services, the EBA aims to bring these activities under direct regulatory supervision. This would mean that platforms offering a simplified front-end for protocols like Aave or other lending markets would need to comply with the same rigorous standards as other regulated financial service providers in the EU. This move is intended to ensure that the decentralized nature of the underlying protocol does not serve as a loophole for intermediaries to avoid consumer protection obligations.
The distinction between direct smart contract interaction and intermediated access is a critical component of the EBA’s analysis. While individuals who interact directly with a blockchain via a command-line interface or a non-custodial wallet without a third-party service provider may remain outside this specific scope, those using a curated “product” or “interface” would fall under the proposed protections. This approach reflects a desire to regulate the points of centralization within the decentralized ecosystem.
Consumer Protection Measures and Leverage Restrictions
A significant portion of the EBA’s response is dedicated to mitigating the risks faced by retail users. The authority has proposed several safeguards that would become mandatory for CASPs facilitating DeFi lending. Among these is the introduction of suitability tests, which would require service providers to assess whether a particular lending or borrowing product is appropriate for a customer’s financial situation and risk tolerance.
Furthermore, the EBA is advocating for the implementation of leverage caps. In the volatile world of crypto-assets, high levels of leverage can lead to rapid liquidations and significant financial loss. By setting limits on the amount of leverage a CASP can offer or facilitate, the EBA hopes to reduce the systemic and individual risks associated with margin-based trading and lending in the DeFi sector. These measures are reminiscent of protections found in traditional derivatives and forex markets.
Transparency is another pillar of the EBA’s proposed safeguards. The authority suggests that CASPs should be required to provide fuller disclosures regarding the risks of DeFi, including explicit warnings about the lack of traditional regulatory safeguards within the decentralized protocols themselves. This ensures that users are fully aware that while the intermediary is regulated, the underlying smart contract may not be subject to the same level of oversight or insurance protections.
Protocol Certification and Technical Standards
Beyond consumer-facing protections, the EBA is looking at the technical integrity of the DeFi protocols that CASPs choose to support. The proposal suggests a potential certification process for lending protocols. This process would be designed to ensure that a protocol is resilient against cyberattacks and functions as intended without critical vulnerabilities in its code.
Such a certification could involve third-party audits or adherence to specific technical standards set by EU regulators. If implemented, this would place a significant burden of due diligence on CASPs. They would essentially be prohibited from offering access to protocols that have not met the required safety benchmarks. This move aims to prevent the proliferation of “rug pulls” or catastrophic protocol failures that have historically plagued the decentralized finance sector.
The EBA also addressed the issue of unauthorized tokens. A specific restriction proposed by the authority would prohibit CASPs from facilitating borrowing or lending for tokens that meet the MiCA definition of asset-referenced tokens (ARTs) or e-money tokens (EMTs) but do not have an authorized issuer within the Union. This is a clear attempt to enforce the stablecoin provisions of MiCA, ensuring that only compliant and regulated stablecoins are used within the intermediated DeFi ecosystem in Europe.
Context of the MiCA Framework
The Markets in Crypto-Assets (MiCA) regulation is the primary legislative structure for the digital asset industry in the European Union. It was designed to provide legal certainty, support innovation, and protect consumers across the member states. However, as the industry evolves, the European Commission has remained open to reviewing and refining the rules to address emerging sectors like DeFi.
The EBA’s focus on the intermediated route is a strategic choice. Regulating “pure” DeFi—where there is no central entity or interface—remains one of the most significant challenges for global regulators. By focusing on the service providers that act as the bridge between the user and the blockchain, the EBA is attempting to apply traditional regulatory logic to a decentralized environment. This approach acknowledges that while the protocol may be decentralized, the business of providing access to it often is not.
This consultation process is part of a broader effort by the EU to remain at the forefront of crypto-asset regulation. The EBA’s role is to provide technical expertise and recommendations, which the European Commission then considers when drafting or amending legislation. The goal is to create a balanced environment where the benefits of blockchain technology can be realized without compromising financial stability or consumer safety.
What Happens Next
The submission of the EBA’s response is a critical step, but it does not signify an immediate change in the law. These recommendations currently constitute requests for legislative assessment rather than enacted rules. The European Commission will now take these suggestions into account as part of its broader review of the MiCA framework.
The targeted consultation on these developments is scheduled to close on September 30 at 11:59 p.m. Central European Summer Time. Following the closure of the consultation, the European Commission will analyze the feedback from the EBA and other stakeholders. Any resulting legislative proposals would then need to move through the standard EU law-making process, involving the European Parliament and the Council of the European Union.
Market participants and CASPs operating within the EU will be watching closely to see which of these recommendations are adopted. The potential for stricter suitability requirements, leverage caps, and protocol certifications could significantly alter the operational landscape for crypto service providers in the region. For now, the industry remains in a period of observation as the regulatory boundaries for DeFi continue to be defined.
